Cross-Site Scripting Vulnerability in Polarion ALM and WebClient
CVE-2021-44478
6.1MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 8 March 2022
Summary
A cross-site scripting vulnerability has been discovered in Polarion ALM and Polarion WebClient for SVN. This vulnerability arises from the inadequate handling of data sent to the web page via the SVN WebClient. Attackers could exploit it by crafting malicious links, which, when accessed by users with administrator privileges, may allow them to execute arbitrary code and extract sensitive information. This poses a significant security risk to users and organizations utilizing the affected versions of the products.
Affected Version(s)
Polarion ALM All versions < V21 R2 P2
Polarion WebClient for SVN All versions
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved